Free tool — no signup

HIPAA & AI Readiness Check

18 questions to find out if you can safely put AI near patient data.

Almost every practice is already using AI — usually before anyone wrote a policy about it. This assessment covers the five areas that actually come up in an audit or an incident: vendor contracts, how PHI moves, who can see what, clinical oversight, and whether your governance paperwork reflects reality. Answer honestly; nobody sees your answers but you.

0 of 18 answered

Vendors & contracts

Has every AI vendor that can touch PHI signed a Business Associate Agreement with you?

Under HIPAA, any vendor creating, receiving, maintaining, or transmitting PHI on your behalf is a business associate. No BAA means no lawful disclosure.

Are you confident no staff member is pasting patient information into a consumer AI account?

Shadow AI is the most common real-world breach path. Free consumer tiers generally have no BAA and may retain inputs.

Do you know which subprocessors and model providers sit behind each AI vendor you use?

Many AI products are a thin layer over a third-party model API. Your PHI may travel further than the vendor name suggests.

Is it contractually confirmed that your data will not be used to train the vendor’s models?

Default consumer terms often permit training on inputs. Enterprise and healthcare tiers usually do not — but only if it is in writing.

How PHI is handled

Does each AI workflow send only the minimum patient information needed to do the job?

The minimum necessary standard applies to AI exactly as it applies to a fax. Sending a whole chart when a problem list would do is a finding waiting to happen.

Where the task does not genuinely need identifiers, are they removed before the data leaves your systems?

De-identified data falls outside HIPAA entirely. Many AI use cases — drafting, summarising, coding support — work perfectly without a name or MRN.

Is PHI encrypted in transit and at rest everywhere the AI workflow touches it?

Encryption is the safe-harbour that determines whether a lost record is a reportable breach or a non-event.

Do you know how long the vendor retains prompts, transcripts, and outputs — and can you delete them?

Audio, transcripts, and prompt logs are PHI. Indefinite vendor retention you cannot purge is a liability you cannot close.

Do you know which countries your patient data is processed and stored in?

Data residency affects state law, payer contracts, and patient trust even where HIPAA itself is silent.

Access & audit

Is access to the AI tool restricted by role, so staff only reach the patients they are permitted to see?

An AI assistant that can query every chart quietly removes the access boundaries your EHR spent years enforcing.

Is every AI interaction involving PHI logged — who asked, what was sent, what came back, when?

You cannot investigate an incident, answer a patient records request, or survive an audit without this trail.

Does AI tool access get revoked the same day someone leaves?

AI tools are frequently missed in offboarding checklists because they were adopted outside IT.

Clinical safety & oversight

Does a qualified human review and attest to every AI-generated output before it enters the record or reaches a patient?

Generated notes, codes, and instructions can be fluent and wrong. Attestation is both a safety control and a documentation requirement.

Is it explicit — in the tool and in policy — that the AI does not diagnose or give medical advice?

Scope creep is how a documentation aid quietly becomes an unregulated clinical decision tool.

For any patient-facing AI, are emergency red flags handled by deterministic rules rather than model judgement?

Chest pain, stroke signs, suicidal ideation, and obstetric bleeding must escalate every single time — not usually.

Is there a defined way for staff to report an AI error, and does someone actually review those reports?

Without a feedback loop you will not learn about failure modes until one causes harm.

Governance & people

Have the staff who use these tools been trained on what they may and may not put into them?

Most AI privacy incidents are ordinary people trying to do their job faster, not bad actors.

Has your HIPAA security risk analysis been updated to include the AI tools you now use?

The Security Rule requires an accurate, current risk analysis. A document that predates your AI adoption is neither.

This is a practical self-assessment, not legal advice or a substitute for a formal HIPAA security risk analysis. Nothing you enter is transmitted — the whole assessment runs in your browser. Confirm your obligations with your compliance counsel before making decisions.